Executive brief
The Testimonials Widget WordPress plugin allows unauthenticated attackers to submit arbitrary URLs that the server will fetch and store as publicly accessible files. An attacker can exploit this to make the vulnerable server connect to internal services, read sensitive responses, and potentially access confidential information or services not directly accessible from the internet.
Technical details
The plugin fails to validate user-supplied URLs in the Featured Image field before performing server-side requests and storing responses as public files. This allows unauthenticated attackers to conduct SSRF attacks (CWE-918) by crafting URLs pointing to internal services. An attacker gains the ability to enumerate internal infrastructure, access restricted endpoints, and exfiltrate sensitive data from services bound to localhost or internal networks.
Affected products
- Testimonials Widget Testimonials Widget through 4.0.4
Timeline
- 2026-09-24: disclosed
- 2026-09-26: advisory